Your password was never the target

0 Comments

Last week the FBI put out an advisory I think every small business owner in Sussex should read — even if you’ve never knowingly read an FBI advisory in your life.

It’s about a phishing kit called Kali365. What makes it worth your attention isn’t that it’s clever, though it is. It’s that it walks straight past multi-factor authentication without ever touching your password. If you’ve spent the last few years being told that MFA is the thing keeping you safe — and plenty of us in IT have told you exactly that — this one bends that assumption.

So here’s what’s actually going on, in plain terms.

It abuses a feature, not a flaw

You know when you sign into Netflix or Amazon Prime on a new smart TV, and instead of typing your password on the telly remote, it gives you a short code and tells you to enter it on a website on your phone? That’s a legitimate, useful piece of technology called device code flow. It lets a device that’s awkward to type on borrow a sign-in from a device that isn’t.

Kali365 abuses exactly that. There’s no fake login page to spot. No dodgy-looking web address. The attacker sends an email dressed up as a normal cloud or document-sharing notification, with a code and an instruction to enter it on a real Microsoft verification page. You go to the genuine Microsoft site — the real one — type the code in, and in that moment you authorise the attacker’s device to access your account.

From there they capture what’s called an OAuth token. Think of it as a wristband the venue gives you after it’s checked your ID at the door: once you’ve got the band, nobody asks for the ID again. With that token, the attacker has your Outlook, Teams and OneDrive without needing your password and without triggering another MFA prompt. The FBI describes it as persistent access, which is the polite way of saying they can keep coming back.

Why this one bothers me

A couple of things.

First, it defeats the mental model most people have been sold. “I’ve got MFA on, so I’m fine” is no longer the full story. MFA still matters enormously — please don’t read this as a reason to turn it off — but it isn’t a finish line.

Second, and this is the bit that should worry smaller organisations: it’s a service. The FBI says Kali365 has been sold on Telegram since around April, and the reporting around it puts the price at roughly $250 a month. For that, a barely-technical attacker gets AI-generated phishing emails, ready-made campaign templates and a dashboard for tracking targets. The skill barrier has effectively been removed. You no longer need a sophisticated adversary to be on the receiving end of a sophisticated attack.

What to actually do about it

The good news is the defences are real and mostly free. They’re configuration, not a product you have to buy.

The single most effective step, straight from the FBI’s advisory, is to restrict device code flow in Microsoft 365. In practice that means:

– Audit where device code flow is genuinely being used first, so you don’t break something legitimate.
– Create a conditional access policy that blocks device code flow for everyone, with narrow exceptions only where a real business process needs it.
– Block authentication transfer between devices.
– If you can’t switch it off entirely, at least exclude your emergency “break-glass” admin accounts so you don’t lock yourself out.

Most small businesses are paying for a Microsoft 365 licence tier that already includes the conditional access controls to do all of this. The capability is usually sitting there unused. If you’ve got an IT provider, this is a perfectly reasonable thing to email them about today: “Have we restricted device code flow, and are our conditional access policies actually doing anything?” If the answer is vague, that tells you something.

The honest version

You can’t train your way out of this one entirely. The whole point of the attack is that the victim does nothing obviously wrong — they enter a code on a genuine Microsoft page. Awareness helps, but the durable fix is in the configuration of your tenant, not in hoping nobody ever has a distracted Tuesday.

If you want to read it yourself rather than take my word for it, it’s FBI IC3 advisory I-052126-PSA, published 21 May 2026. Worth ten minutes of anyone’s time.

And if you’re not sure whether your own Microsoft 365 is set up to deal with this, that’s exactly the kind of thing worth checking before it’s a problem rather than after.

Kali365 phishing attack illustration
Categories: